Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
2026-04-21 • Trend Micro •
Trend Micro found Void Dokkaebi, also tracked as Famous Chollima, turning fake recruiter interviews into a worm-like supply chain campaign against software developers. Victims are lured into cloning repositories that abuse VS Code folder-open tasks, and compromised machines are then used to inject obfuscated JavaScript into configuration and entry-point files that execute during normal Node.js build, linting, or bundling activity. The actor rewrites Git history with backdated force-pushes and preserved commit metadata to hide tampering, with more than 750 infected repositories, over 500 malicious VS Code task configurations, and 101 commit-tampering tool instances observed in March 2026. The campaign delivered a DEV#POPPER RAT variant and staged payloads through blockchain infrastructure including Tron, Aptos, and Binance Smart Chain, making takedown harder. The activity matters because a single compromised developer account can seed organizational and open-source repositories, exposing contributors, forks, and downstream projects through trusted development workflows.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 198.105.127.210 | 2026-03-05 | 2026-06-12 |
| IPv4 | 23.27.202.27 | 2025-10-20 | 2026-06-12 |
| DOMAIN | api.trongrid.io | 2025-10-27 | 2026-05-31 |
| DOMAIN | fullnode.mainnet.aptoslabs.com | 2025-10-27 | 2026-05-31 |
| IPv4 | 154.91.0.196 | 2026-04-21 | 2026-04-21 |
| IPv4 | 83.168.68.219 | 2026-04-21 | 2026-04-21 |
| IPv4 | 23.27.120.142 | 2025-10-20 | 2026-04-21 |
| IPv4 | 85.239.62.36 | 2025-10-20 | 2026-04-21 |
| IPv4 | 23.27.20.143 | 2025-10-20 | 2026-04-21 |
| IPv4 | 136.0.9.8 | 2025-10-20 | 2026-04-21 |
| IPv4 | 166.88.4.2 | 2025-10-20 | 2026-04-21 |